Privacy Policy
Last updated: [EFFECTIVE DATE — pending review]
Provenly is operated by GetMax Healthcare Solutions Pvt Ltd(“Provenly”, “we”, “us”). This policy explains what personal data we collect, why, how we protect it, and the choices you have. Questions: sriram@getmaxrcm.com.
1. Data we collect
- Account & profile: name, email, password (hashed), phone (optional), headline, experience, education, skills, desired salary (optional), and a public profile slug if you choose one.
- Documents: resumes and any documents you upload to your private vault (e.g. payslips, IDs) — stored privately and visible only to you unless you share them.
- References: the name, email and company of referees you ask us to contact, and their responses.
- Imports: if you import from LinkedIn or GitHub, the public profile data you direct us to fetch.
- Usage: standard log data (IP, device, pages) for security and reliability.
2. How we use it
- To build and host your verified profile and proof page.
- To match you with relevant open roles, and — only if you make your profile public — to let employers discover and contact you.
- To run verification requests with the referees you nominate.
- To provide AI tools (resume polish, profile drafting) on data you submit.
- To secure the service and meet legal obligations.
We do not sell your personal data.
3. Visibility & your control
Your profile is private by default. You choose whether to make it public; you can change this any time in Settings. Your document vault is always private to you. You can edit or delete your profile, and delete your account entirely (Settings → Delete account), which removes your data subject to any legal retention requirements.
4. Service providers (sub-processors)
We use trusted processors to run Provenly. They process data only on our instructions:
- Supabase — database, authentication, and file storage.
- Vercel — application hosting and delivery.
- Resend — transactional email (e.g. verification, notifications).
- Anthropic — AI features; text you submit to resume/profile tools is processed to generate output.
- Apify — used only when you explicitly import a public LinkedIn profile.
5. Security
We apply row-level access controls so your data is only accessible to you (and to employers only when you make your profile public). Documents are stored in private, owner-scoped storage and served via expiring links. See our Security page for more.
6. Your rights
You may access, correct, export, or delete your data. To exercise these rights, use your account settings or email sriram@getmaxrcm.com.
7. Changes
We may update this policy; material changes will be reflected here with a new date. Continued use after an update means you accept the revised policy.